You can subscribe to this list here.
2006 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(1) |
Jul
(1) |
Aug
|
Sep
|
Oct
(2) |
Nov
(1) |
Dec
(20) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2007 |
Jan
(91) |
Feb
(111) |
Mar
(226) |
Apr
(65) |
May
(197) |
Jun
(202) |
Jul
(92) |
Aug
(87) |
Sep
(120) |
Oct
(133) |
Nov
(89) |
Dec
(155) |
2008 |
Jan
(251) |
Feb
(136) |
Mar
(174) |
Apr
(149) |
May
(56) |
Jun
(32) |
Jul
(36) |
Aug
(171) |
Sep
(245) |
Oct
(244) |
Nov
(218) |
Dec
(272) |
2009 |
Jan
(113) |
Feb
(119) |
Mar
(192) |
Apr
(117) |
May
(93) |
Jun
(46) |
Jul
(80) |
Aug
(54) |
Sep
(109) |
Oct
(70) |
Nov
(145) |
Dec
(110) |
2010 |
Jan
(137) |
Feb
(87) |
Mar
(45) |
Apr
(157) |
May
(58) |
Jun
(99) |
Jul
(188) |
Aug
(136) |
Sep
(101) |
Oct
(100) |
Nov
(61) |
Dec
(60) |
2011 |
Jan
(84) |
Feb
(43) |
Mar
(70) |
Apr
(17) |
May
(69) |
Jun
(28) |
Jul
(43) |
Aug
(21) |
Sep
(151) |
Oct
(120) |
Nov
(84) |
Dec
(101) |
2012 |
Jan
(119) |
Feb
(82) |
Mar
(70) |
Apr
(115) |
May
(66) |
Jun
(131) |
Jul
(70) |
Aug
(65) |
Sep
(66) |
Oct
(86) |
Nov
(197) |
Dec
(81) |
2013 |
Jan
(65) |
Feb
(48) |
Mar
(32) |
Apr
(68) |
May
(98) |
Jun
(59) |
Jul
(41) |
Aug
(52) |
Sep
(42) |
Oct
(37) |
Nov
(10) |
Dec
(27) |
2014 |
Jan
(61) |
Feb
(34) |
Mar
(30) |
Apr
(52) |
May
(45) |
Jun
(40) |
Jul
(28) |
Aug
(9) |
Sep
(39) |
Oct
(69) |
Nov
(55) |
Dec
(19) |
2015 |
Jan
(13) |
Feb
(21) |
Mar
(5) |
Apr
(14) |
May
(30) |
Jun
(51) |
Jul
(31) |
Aug
(12) |
Sep
(29) |
Oct
(15) |
Nov
(24) |
Dec
(16) |
2016 |
Jan
(62) |
Feb
(76) |
Mar
(30) |
Apr
(43) |
May
(46) |
Jun
(62) |
Jul
(21) |
Aug
(49) |
Sep
(67) |
Oct
(27) |
Nov
(26) |
Dec
(38) |
2017 |
Jan
(7) |
Feb
(12) |
Mar
(69) |
Apr
(59) |
May
(54) |
Jun
(40) |
Jul
(76) |
Aug
(82) |
Sep
(92) |
Oct
(51) |
Nov
(32) |
Dec
(30) |
2018 |
Jan
(22) |
Feb
(25) |
Mar
(34) |
Apr
(35) |
May
(37) |
Jun
(21) |
Jul
(69) |
Aug
(55) |
Sep
(17) |
Oct
(67) |
Nov
(9) |
Dec
(5) |
2019 |
Jan
(19) |
Feb
(12) |
Mar
(15) |
Apr
(19) |
May
|
Jun
(27) |
Jul
(27) |
Aug
(25) |
Sep
(25) |
Oct
(27) |
Nov
(10) |
Dec
(14) |
2020 |
Jan
(22) |
Feb
(20) |
Mar
(36) |
Apr
(40) |
May
(52) |
Jun
(35) |
Jul
(21) |
Aug
(32) |
Sep
(71) |
Oct
(27) |
Nov
(11) |
Dec
(16) |
2021 |
Jan
(16) |
Feb
(21) |
Mar
(21) |
Apr
(27) |
May
(17) |
Jun
|
Jul
(2) |
Aug
(22) |
Sep
(23) |
Oct
(7) |
Nov
(11) |
Dec
(28) |
2022 |
Jan
(23) |
Feb
(18) |
Mar
(9) |
Apr
(15) |
May
(15) |
Jun
(7) |
Jul
(8) |
Aug
(15) |
Sep
(1) |
Oct
|
Nov
(11) |
Dec
(10) |
2023 |
Jan
(14) |
Feb
(10) |
Mar
(11) |
Apr
(13) |
May
(2) |
Jun
(30) |
Jul
(1) |
Aug
(15) |
Sep
(13) |
Oct
(3) |
Nov
(25) |
Dec
(5) |
2024 |
Jan
(3) |
Feb
(10) |
Mar
(9) |
Apr
|
May
(1) |
Jun
(15) |
Jul
(7) |
Aug
(10) |
Sep
(3) |
Oct
(8) |
Nov
(6) |
Dec
(15) |
2025 |
Jan
(3) |
Feb
(1) |
Mar
(7) |
Apr
(5) |
May
(13) |
Jun
(16) |
Jul
(1) |
Aug
(6) |
Sep
|
Oct
|
Nov
|
Dec
|
From: Lonnie A. <li...@lo...> - 2017-09-04 00:02:18
|
Michael, Out of curiosity, how may cores does your VM guest have ? If it is only 1 possibly that could be an issue, if so you might try 2. I haven't used Monit too much, so no insights there. Lonnie On Sep 3, 2017, at 6:11 PM, Michael Knill <mic...@ip...> wrote: > Hi Group > > I have just installed a new system in a very busy clinic and I am starting to get a few Monit Resource Limit Alerts. I have been getting loads >2 and >4. > The confusing thing is that it is a VM so Im not quite sure whether a) my load limit configuration is correct in Monit and b) I have enough resources allocated. > > Any ideas on what I should be doing here? > > Regards > Michael Knill |
From: Michael K. <mic...@ip...> - 2017-09-03 23:11:41
|
Hi Group I have just installed a new system in a very busy clinic and I am starting to get a few Monit Resource Limit Alerts. I have been getting loads >2 and >4. The confusing thing is that it is a VM so Im not quite sure whether a) my load limit configuration is correct in Monit and b) I have enough resources allocated. Any ideas on what I should be doing here? Regards Michael Knill |
From: David K. <da...@ke...> - 2017-09-03 18:19:07
|
Hi Roberto, not sure if you got a reply to this. Adaptive Ban is included with AstLinux. On the network tab of the web interface look for the Adaptive Ban firewall plugin in the list and then click on Configure Plugin and make sure that ENABLED=1 You can also use an external block list that is updated with reported "bad" IP addresses. See instructions here... https://doc.astlinux-project.org/userdoc:tt_firewall_external_block_list Restart the firewall after making any changes. David On Thu, Aug 31, 2017 at 4:14 PM, Roberto Rivera <rri...@gm...> wrote: > Hi all, > I have a lot of foreign ip addresses making attempts to hack into my PBX. > What is the easiest way to block these addresses? > I saw the Astlinux firewall documentation that says I need to go to the > Network tab>click the firewall button in but then I'm not sure if there is > anything else I need to do? I also saw something regarding Adaptive Ban. Is > that included with Astlinux. > Any comments would be appreciated. > I'm using Alix box. > Thanks > > Sent from my iPhone > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to > pa...@kr.... > |
From: Lonnie A. <li...@lo...> - 2017-09-02 17:53:08
|
Hi Peter, Good to hear you got it working. The "accept_ra", "autoconf" and "forwarding" settings are interrelated and can be confusing. Such as to enable "accept_ra" must be 2 if "forwarding" is 1 . Personally I have a Business ISP account with "static" prefixes, and so far they have been static, but I would not bet that will *always* be true. "Stuff" happens. If you only have a couple server devices like AstLinux that you use a GUA with, it is not a big deal to change them for a ISP hiccup or switching to a different ISP. But in more complex situations, say you want a IPv6 /64 prefix off a LAN on your AstLinux box ... when your GUA prefix changes it effects *all* your internal GUA address. Possibly pfSense supports Prefix Delegation Server where AstLinux could use DHCPv6-PD to autoconfig internal LAN's. Even with a Business ISP account with "static" GUA IPv6 prefixes, I use ULA's for all my internal addresses and prefixes with NPTv6 enabled at the edge. Lonnie On Sep 2, 2017, at 12:06 PM, Dr. Peter Voigt <pv...@uo...> wrote: > Hi Lonnie, > > wow, what a detailed answer - thank you very much. > > I have just tested option 1) successfully on my AstLinux machine. It is > exactly what I am looking for in my current state of understanding > IPv6. > > Option 1) is obviously a standard Linux sysctl that I was not aware of. > Nevertheless, it would be nice, if this could be done from the WebGUI > or otherwise be documented in the AstLinux documentation. This lesson > learned I have just compared to the settings of my Debian Stretch > machines: > > # cat /proc/sys/net/ipv6/conf/eth0/accept_ra > 1 > # cat /proc/sys/net/ipv6/conf/eth0/autoconf > 1 > # cat /proc/sys/net/ipv6/conf/eth0/forwarding > 0 > > I am still far away from understanding IPv6 concepts but I know already > as much, that I have started hating the dynamic prefix sent from my > internet provider. One big "advantage" of IPv6 over IPv4: A prefix > change gives all my machines new IPv6 addresses while a dynamic IPv4 > address just changes the router WAN IP ;-). But to be fair: My prefix > only changes when my pfSense machine needs a reboot. I have heard about > other providers changing customer prefix even on a daily basis. > > Due to the dynamic prefix I will have to go into details of the ULA > concept. But may be I will come to the conclusion that I need to get a > more expensive business contract with my provider ensuring a static > prefix even during reboots of my pfSense machine. > > Thank you very much, > Peter > > > On Sat, 2 Sep 2017 10:30:18 -0500 > Lonnie Abelbeck <li...@lo...> wrote: > >> Hi Peter, >> >> You have many options, here are 5 in no particular order. >> >> Option 1) >> Since you have the AstLinux firewall disabled, you need to create a >> short startup script, create the file /mnt/kd/rc.elocal ... >> -- /mnt/kd/rc.elocal -- #!/bin/sh >> >> . /etc/rc.conf >> >> echo "[rc.elocal] Enabling autoconf SLAAC on $EXTIF" >> sysctl -w net/ipv6/conf/$EXTIF/accept_ra=2 >/dev/null >> sysctl -w net/ipv6/conf/$EXTIF/autoconf=1 >/dev/null >> >> exit 0 >> -- >> >> Then make it executable ... >> -- >> chmod 755 /mnt/kd/rc.elocal >> -- >> Manually running /mnt/kd/rc.elocal or a reboot will enable the sysctl >> settings. Note that it can take awhile before the RA's are received. >> >> >> Option 2) >> If you enabled the AstLinux firewall (with a single interface would >> need to allow TCP 80,443,22 and such to continue to manage it) then >> you could add a firewall related config variable IP_FORWARDING=0 ... >> -- add to /mnt/kd/rc.conf.d/user.conf -- IP_FORWARDING=0 -- >> This only works if you are using one interface, no AstLinux OpenVPN, >> etc. . >> >> >> Option 3) >> If you have static IPv6 prefixes from your ISP (not typical except >> for Business accounts) you could set static addresses ... >> >> Network tab -> External Interface: -> Connection Type: [ Static IP ] >> and define Static IPv4 and IPv6 addresses Note: if IPv6 Gateway: is >> left empty it use a Router Advertisement (RA) to set the default IPv6 >> route. >> >> A /64 prefix gives you a lot of addresses to pick a unique non-SLACC >> static IPv6 for your AstLinux box. >> >> >> Option 4) >> If you have dynamic IPv6 prefixes from your ISP (typical) you could >> set static ULA addresses (fdnn:... addresses) with pfSense doing >> Network Prefix Translation (NPTv6) at the edge. >> >> Same configuration as with "Option 3" but using a ULA instead of a >> GUA. ULA's have the advantage they are always static to your >> internal network, and can be mapped to GUA's at the router's edge. >> >> While this documentation applies to AstLinux as the router, the >> terminology and references may be helpful: IPv6 ULA / NPTv6 >> Configuration >> https://doc.astlinux-project.org/userdoc:tt_ipv6_ula_nptv6_config >> >> >> Option 5) >> If your pfSense configuration supports DHCPv6 server, you could >> enable DHCPv6 client on your external interface. >> >> Network tab -> External Interface: -> Connection Type: [ Static >> IPv4/DHCPv6 ] and define under External DHCPv6 Client Settings: >> >> DHCPv6 Client Address: [ enabled ] >> DHCPv6 Prefix Delegation: [ disabled ] >> >> Reboot to apply any changes. >> >> >> Summary) >> The simplest is probably "Option 1" to answer your question, given >> your current configuration. >> >> Personally I'm a big fan of using ULA's "Option 4" on my internal >> network. Use AstLinux's "unique-local-ipv6" command from the CLI, >> generate one you like, write it down and use it for all your internal >> IPv6, forever. Carve up the /48 into /64's of your choosing. One >> drawback is it requires manual documentation keeping track of ULA's >> and ULA prefixes you use. On the plus side, ULA's are simple, and >> if/when the GUA prefix changes your internal ULA IPv6 will not miss a >> beat. >> >> Hope this was more helpful than confusing. :-) Understanding these >> options will help you learn IPv6. >> >> Lonnie >> > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > |
From: Dr. P. V. <pv...@uo...> - 2017-09-02 17:06:47
|
Hi Lonnie, wow, what a detailed answer - thank you very much. I have just tested option 1) successfully on my AstLinux machine. It is exactly what I am looking for in my current state of understanding IPv6. Option 1) is obviously a standard Linux sysctl that I was not aware of. Nevertheless, it would be nice, if this could be done from the WebGUI or otherwise be documented in the AstLinux documentation. This lesson learned I have just compared to the settings of my Debian Stretch machines: # cat /proc/sys/net/ipv6/conf/eth0/accept_ra 1 # cat /proc/sys/net/ipv6/conf/eth0/autoconf 1 # cat /proc/sys/net/ipv6/conf/eth0/forwarding 0 I am still far away from understanding IPv6 concepts but I know already as much, that I have started hating the dynamic prefix sent from my internet provider. One big "advantage" of IPv6 over IPv4: A prefix change gives all my machines new IPv6 addresses while a dynamic IPv4 address just changes the router WAN IP ;-). But to be fair: My prefix only changes when my pfSense machine needs a reboot. I have heard about other providers changing customer prefix even on a daily basis. Due to the dynamic prefix I will have to go into details of the ULA concept. But may be I will come to the conclusion that I need to get a more expensive business contract with my provider ensuring a static prefix even during reboots of my pfSense machine. Thank you very much, Peter On Sat, 2 Sep 2017 10:30:18 -0500 Lonnie Abelbeck <li...@lo...> wrote: > Hi Peter, > > You have many options, here are 5 in no particular order. > > Option 1) > Since you have the AstLinux firewall disabled, you need to create a > short startup script, create the file /mnt/kd/rc.elocal ... > -- /mnt/kd/rc.elocal -- #!/bin/sh > > . /etc/rc.conf > > echo "[rc.elocal] Enabling autoconf SLAAC on $EXTIF" > sysctl -w net/ipv6/conf/$EXTIF/accept_ra=2 >/dev/null > sysctl -w net/ipv6/conf/$EXTIF/autoconf=1 >/dev/null > > exit 0 > -- > > Then make it executable ... > -- > chmod 755 /mnt/kd/rc.elocal > -- > Manually running /mnt/kd/rc.elocal or a reboot will enable the sysctl > settings. Note that it can take awhile before the RA's are received. > > > Option 2) > If you enabled the AstLinux firewall (with a single interface would > need to allow TCP 80,443,22 and such to continue to manage it) then > you could add a firewall related config variable IP_FORWARDING=0 ... > -- add to /mnt/kd/rc.conf.d/user.conf -- IP_FORWARDING=0 -- > This only works if you are using one interface, no AstLinux OpenVPN, > etc. . > > > Option 3) > If you have static IPv6 prefixes from your ISP (not typical except > for Business accounts) you could set static addresses ... > > Network tab -> External Interface: -> Connection Type: [ Static IP ] > and define Static IPv4 and IPv6 addresses Note: if IPv6 Gateway: is > left empty it use a Router Advertisement (RA) to set the default IPv6 > route. > > A /64 prefix gives you a lot of addresses to pick a unique non-SLACC > static IPv6 for your AstLinux box. > > > Option 4) > If you have dynamic IPv6 prefixes from your ISP (typical) you could > set static ULA addresses (fdnn:... addresses) with pfSense doing > Network Prefix Translation (NPTv6) at the edge. > > Same configuration as with "Option 3" but using a ULA instead of a > GUA. ULA's have the advantage they are always static to your > internal network, and can be mapped to GUA's at the router's edge. > > While this documentation applies to AstLinux as the router, the > terminology and references may be helpful: IPv6 ULA / NPTv6 > Configuration > https://doc.astlinux-project.org/userdoc:tt_ipv6_ula_nptv6_config > > > Option 5) > If your pfSense configuration supports DHCPv6 server, you could > enable DHCPv6 client on your external interface. > > Network tab -> External Interface: -> Connection Type: [ Static > IPv4/DHCPv6 ] and define under External DHCPv6 Client Settings: > > DHCPv6 Client Address: [ enabled ] > DHCPv6 Prefix Delegation: [ disabled ] > > Reboot to apply any changes. > > > Summary) > The simplest is probably "Option 1" to answer your question, given > your current configuration. > > Personally I'm a big fan of using ULA's "Option 4" on my internal > network. Use AstLinux's "unique-local-ipv6" command from the CLI, > generate one you like, write it down and use it for all your internal > IPv6, forever. Carve up the /48 into /64's of your choosing. One > drawback is it requires manual documentation keeping track of ULA's > and ULA prefixes you use. On the plus side, ULA's are simple, and > if/when the GUA prefix changes your internal ULA IPv6 will not miss a > beat. > > Hope this was more helpful than confusing. :-) Understanding these > options will help you learn IPv6. > > Lonnie > |
From: Lonnie A. <li...@lo...> - 2017-09-02 15:30:30
|
Hi Peter, You have many options, here are 5 in no particular order. Option 1) Since you have the AstLinux firewall disabled, you need to create a short startup script, create the file /mnt/kd/rc.elocal ... -- /mnt/kd/rc.elocal -- #!/bin/sh . /etc/rc.conf echo "[rc.elocal] Enabling autoconf SLAAC on $EXTIF" sysctl -w net/ipv6/conf/$EXTIF/accept_ra=2 >/dev/null sysctl -w net/ipv6/conf/$EXTIF/autoconf=1 >/dev/null exit 0 -- Then make it executable ... -- chmod 755 /mnt/kd/rc.elocal -- Manually running /mnt/kd/rc.elocal or a reboot will enable the sysctl settings. Note that it can take awhile before the RA's are received. Option 2) If you enabled the AstLinux firewall (with a single interface would need to allow TCP 80,443,22 and such to continue to manage it) then you could add a firewall related config variable IP_FORWARDING=0 ... -- add to /mnt/kd/rc.conf.d/user.conf -- IP_FORWARDING=0 -- This only works if you are using one interface, no AstLinux OpenVPN, etc. . Option 3) If you have static IPv6 prefixes from your ISP (not typical except for Business accounts) you could set static addresses ... Network tab -> External Interface: -> Connection Type: [ Static IP ] and define Static IPv4 and IPv6 addresses Note: if IPv6 Gateway: is left empty it use a Router Advertisement (RA) to set the default IPv6 route. A /64 prefix gives you a lot of addresses to pick a unique non-SLACC static IPv6 for your AstLinux box. Option 4) If you have dynamic IPv6 prefixes from your ISP (typical) you could set static ULA addresses (fdnn:... addresses) with pfSense doing Network Prefix Translation (NPTv6) at the edge. Same configuration as with "Option 3" but using a ULA instead of a GUA. ULA's have the advantage they are always static to your internal network, and can be mapped to GUA's at the router's edge. While this documentation applies to AstLinux as the router, the terminology and references may be helpful: IPv6 ULA / NPTv6 Configuration https://doc.astlinux-project.org/userdoc:tt_ipv6_ula_nptv6_config Option 5) If your pfSense configuration supports DHCPv6 server, you could enable DHCPv6 client on your external interface. Network tab -> External Interface: -> Connection Type: [ Static IPv4/DHCPv6 ] and define under External DHCPv6 Client Settings: DHCPv6 Client Address: [ enabled ] DHCPv6 Prefix Delegation: [ disabled ] Reboot to apply any changes. Summary) The simplest is probably "Option 1" to answer your question, given your current configuration. Personally I'm a big fan of using ULA's "Option 4" on my internal network. Use AstLinux's "unique-local-ipv6" command from the CLI, generate one you like, write it down and use it for all your internal IPv6, forever. Carve up the /48 into /64's of your choosing. One drawback is it requires manual documentation keeping track of ULA's and ULA prefixes you use. On the plus side, ULA's are simple, and if/when the GUA prefix changes your internal ULA IPv6 will not miss a beat. Hope this was more helpful than confusing. :-) Understanding these options will help you learn IPv6. Lonnie On Sep 2, 2017, at 6:23 AM, Dr. Peter Voigt <pv...@uo...> wrote: > My AstLinux is installed on an APU1D4 behind a pfSense machine, e.g. the > AstLinux firewall is disabled and the only AstLinux interface I am > using is "external interface on eth0". AstLinux is working now for > about two years without any issues. > > I have recently discovered that my ISP provides real dual stack > IPv4/IPv6 connectivity. Therefore I have started to play with IPv6 to > improve my knowledge. I changed the pfSense configuration to obtain an > IPv6 address besides the IPv4 one. Furthermore, I am using stateless > autoconfiguration (SLAAC) to provide IPv6 global addresses to my > various devices in my different wired and wireless home networks. This > works fine with all devices tested so far. > > No I would like to obtain a global IPv6 address on the external > interface of AstLinux. I tested various configurations on the page > "Network Configuration Settings" and subsections "External Interface" > and "External DHCPv6 Client Settings" of the WebGUI without success so > far. All I could achive is a link-local address for the external > interface but I would like to obtain a global IPv6 address from pfSense. > > I appreciate any comments on this. As I have just recently started to > learn IPv6, I may even suffer from a basic misunderstanding. > > Thanks in advance, > Peter |
From: Dr. P. V. <pv...@uo...> - 2017-09-02 12:02:39
|
My AstLinux is installed on an APU1D4 behind a pfSense machine, e.g. the AstLinux firewall is disabled and the only AstLinux interface I am using is "external interface on eth0". AstLinux is working now for about two years without any issues. I have recently discovered that my ISP provides real dual stack IPv4/IPv6 connectivity. Therefore I have started to play with IPv6 to improve my knowledge. I changed the pfSense configuration to obtain an IPv6 address besides the IPv4 one. Furthermore, I am using stateless autoconfiguration (SLAAC) to provide IPv6 global addresses to my various devices in my different wired and wireless home networks. This works fine with all devices tested so far. No I would like to obtain a global IPv6 address on the external interface of AstLinux. I tested various configurations on the page "Network Configuration Settings" and subsections "External Interface" and "External DHCPv6 Client Settings" of the WebGUI without success so far. All I could achive is a link-local address for the external interface but I would like to obtain a global IPv6 address from pfSense. I appreciate any comments on this. As I have just recently started to learn IPv6, I may even suffer from a basic misunderstanding. Thanks in advance, Peter |
From: John N. <jn...@co...> - 2017-09-02 00:44:43
|
Cody Alderson wrote: > John, > > Comments in line. > > > What provider and what protocol? > > > VoIP.ms and SIP Change your account and Asterisk to IAX. this can be done with voip.ms easily. They even supply sample configs With an Asterisk box working there is no reason to use SIP and have a giant red flag on your back. Shut off any open SIP ports After this is done, are there any attempts? If so , what ports? As to passwords, I was referencing the Asterisk/AstLinux defaults for https and SSH. If these ports are turned off in your router except when Josh or ?? is helping with configuration changes, they should not be an issue JN > > > Suggestions: > Make sure your passwords are changed and strong. > Your ( external ) router is your first line of defense! > > Yes, I agree. I use complicated passwords. Is there a recommended character length? > > > -Cody > -- Dog is my Co-pilot |
From: Cody A. <ald...@gm...> - 2017-09-01 23:18:54
|
John, Comments in line. What provider and what protocol? > VoIP.ms and SIP > > > Suggestions: > Make sure your passwords are changed and strong. > Your ( external ) router is your first line of defense! > > Yes, I agree. I use complicated passwords. Is there a recommended character length? -Cody |
From: Lonnie A. <li...@lo...> - 2017-09-01 16:50:30
|
Hi Cody, From John's post your CNET (Collector's Network) is IAX2 based, and he explained things well. Enabling the Adaptive Ban plugin is still useful for IAX2 . You ask a good general question, for most all other situations SIP is used, here are some security measures that can be used: 1) Using the Adaptive Ban plugin is a great first step. 2) If you had a known list of static IPv4 address that need remote SIP access use the Firewall sub-tap to "Pass EXT->Local" UDP 5060 for only those IP's. Don't use Source: 0/0 in this case. 3) If you had a known list of dynamic hostnames that need remote SIP access use the Firewall DynDNS Host Open plugin to DYNDNS_HOST_OPEN_UDP="sip1.example.com~5060 sip2.example.com~5060" etc. 4) You can either blacklist or whitelist access by SIP User-Agent strings by using the Firewall SIP User-Agent plugin. Keep in mind if your AstLinux box is at the edge (public IPv4 address) and it is only accessing a SIP trunk upstream by registering (ie. no remote SIP clients), then the stateful firewall will automatically track the upstream SIP server connections and *no* SIP related firewall rules need to be added. If this is the case none of the security measures 1-4 above are needed for Asterisk. Security by obscurity, use SIP TCP/TLS for remote SIP clients, and don't expose UDP 5060 externally. If your ISP offers native IPv6, only expose IPv6 SIP (assuming all SIP clients have native IPv6 access). Finally, this applies to most every situation, make use of the *.netset Blocklists, at least firehol_level1 and voipbl are good basic choices which should not usually cause false-positive blocking. More info ... Firewall External Block List https://doc.astlinux-project.org/userdoc:tt_firewall_external_block_list Lonnie On Sep 1, 2017, at 10:38 AM, Cody Alderson <ald...@gm...> wrote: > Hi, > > I am connected to CNET (Collector's Network) and have one incoming VoIP line running in Astlinux. Outgoing calls over the VoIP number have been redundantly disabled in Asterisk and at the VoIP service providers setup options. My Astlinux is constantly bombarded with attempts to get in by unauthorized users. I currently have Adaptive Ban enabled, and, with help already received here, have set the system to keep a record of the IP addresses for the bans to persist after a reboot. > > I was wondering what other security I should implement. Keep in mind that the box is an older HP thin client, but the traffic is very minimal. I get a lot more traffic trying to break in than the box needs to handle for legitimate use. :) > > If you suggest enabling another security feature, would you be so kind as to point me to some instructions on configuring it? > > Thank you in advance, > > -Cody |
From: John N. <jn...@co...> - 2017-09-01 16:11:53
|
Cody Alderson wrote: > Hi, > > I am connected to CNET (Collector's Network) In reality The Collectors Network is not a true network with a constant connection. There is a reference point that provides the called node's IP address from a dialed number. In the US it is 1+NXX-XXXX. Once the number to IP is resolved, it is peer to peer. Inbound calls are not authenticated, use the IAX protocol, and are rejected if the called number doesn't match along with a specified context > and have one incoming VoIP line running in Astlinux. What provider and what protocol? I use voip.ms and the IAX protocol and have no issues with attempts. I do NOT use SIP on the WAN and have no SIP related ports open on my router Your older HP5720 is a good match for AstLinux, and there are more than 30 nodes on the Collectors network using these thin clients without any extra security measures. Suggestions: Make sure your passwords are changed and strong. Your ( external ) router is your first line of defense! IF you have SSH open on your router, use a non standard port. Open it only when someone is helping you with configurations. Same with https port 443 Don't have 5060 open on your router. If you are using a PSTN provider that only supports SIP, you will register to them and will not need a port open IAX is not more secure than SIP but is seldom if ever the target of an attack John Novack > Outgoing calls over the VoIP number have been redundantly disabled in Asterisk and at the VoIP service providers setup options. My Astlinux is constantly bombarded with attempts to get in by unauthorized users. I currently have Adaptive Ban enabled, and, with help already received here, have set the system to keep a record of the IP addresses for the bans to persist after a reboot. > > I was wondering what other security I should implement. Keep in mind that the box is an older HP thin client, but the traffic is very minimal. I get a lot more traffic trying to break in than the box needs to handle for legitimate use. :) > > If you suggest enabling another security feature, would you be so kind as to point me to some instructions on configuring it? > > Thank you in advance, > > -Cody > > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... -- Dog is my Co-pilot |
From: Cody A. <ald...@gm...> - 2017-09-01 15:38:48
|
Hi, I am connected to CNET (Collector's Network) and have one incoming VoIP line running in Astlinux. Outgoing calls over the VoIP number have been redundantly disabled in Asterisk and at the VoIP service providers setup options. My Astlinux is constantly bombarded with attempts to get in by unauthorized users. I currently have Adaptive Ban enabled, and, with help already received here, have set the system to keep a record of the IP addresses for the bans to persist after a reboot. I was wondering what other security I should implement. Keep in mind that the box is an older HP thin client, but the traffic is very minimal. I get a lot more traffic trying to break in than the box needs to handle for legitimate use. :) If you suggest enabling another security feature, would you be so kind as to point me to some instructions on configuring it? Thank you in advance, -Cody |
From: Roberto R. <rri...@gm...> - 2017-08-31 20:14:55
|
Hi all, I have a lot of foreign ip addresses making attempts to hack into my PBX. What is the easiest way to block these addresses? I saw the Astlinux firewall documentation that says I need to go to the Network tab>click the firewall button in but then I'm not sure if there is anything else I need to do? I also saw something regarding Adaptive Ban. Is that included with Astlinux. Any comments would be appreciated. I'm using Alix box. Thanks Sent from my iPhone |
From: Michael K. <mic...@ip...> - 2017-08-31 07:16:04
|
Yep already turned these off! Regards Michael Knill -----Original Message----- From: Michael Keuter <li...@mk...> Reply-To: AstLinux List <ast...@li...> Date: Thursday, 31 August 2017 at 4:57 pm To: AstLinux List <ast...@li...> Subject: Re: [Astlinux-users] Getting high processor load on ALIX box > Am 31.08.2017 um 05:47 schrieb Michael Knill <mic...@ip...>: > > Ok after dropping out Monit and Darkstat and rebooting (it didn't free up the memory until I did), I now have above 50M free on my systems so that's not ideal but workable. > I will not bother upgrading just yet. Maybe next year ☺ > > Regards > Michael Knill Also Asterisk 13 needs more RAM then Asterisk 11. But if don't need PJSIP or ARI you can configure Asterisk to not load these modules. > From: Michael Knill <mic...@ip...> > Reply-To: AstLinux List <ast...@li...> > Date: Wednesday, 30 August 2017 at 5:56 pm > To: AstLinux List <ast...@li...> > Subject: Re: [Astlinux-users] Getting high processor load on ALIX box > > Thanks Michael. I will make sure I turn off Monit on all my ALIX boxes. > I get that I can fine tune things to make them work but frankly for the money I think I will just change them all out to APU’s or not upgrade. > > Regards > Michael Knill > > From: Michael Keuter <li...@mk...> > Reply-To: AstLinux List <ast...@li...> > Date: Wednesday, 30 August 2017 at 5:40 pm > To: AstLinux List <ast...@li...> > Subject: Re: [Astlinux-users] Getting high processor load on ALIX box > > > > > Am 30.08.2017 um 05:17 schrieb Michael Knill <mic...@ip...>: > > Hmm looks like Monit will need to go as nearly 15M. > Chrony is also fairly heavy on memory. Is this all I have in 1.2.10? > Do I disable SNMP by just removing mnt/kd/snmp/snmpd.conf ? > I have PHP using 45M plus. Is this normal? Anything I can do in php.ini? > > Regards > Michael Knill > > -----Original Message----- > From: Michael Knill <mic...@ip...> > Reply-To: AstLinux List <ast...@li...> > Date: Wednesday, 30 August 2017 at 12:45 pm > To: AstLinux List <ast...@li...> > Subject: Re: [Astlinux-users] Getting high processor load on ALIX box > > Hmm Im a bit worried actually about upgrading to 1.2.10 with Asterisk 13 on my ALIX boxes. > Some sites showing 5M free. > > Regards > Michael Knill > > -----Original Message----- > From: Lonnie Abelbeck <li...@lo...> > Reply-To: AstLinux List <ast...@li...> > Date: Wednesday, 30 August 2017 at 12:13 pm > To: AstLinux List <ast...@li...> > Subject: Re: [Astlinux-users] Getting high processor load on ALIX box > > Michael, > > Since this is an ALIX box, (low RAM, low performance) best to not enable anything "extra" IMHO. > > Lonnie > > > On Aug 29, 2017, at 8:45 PM, Michael Knill <mic...@ip...> wrote: > > > > So do you think I should turn it off by default and only turn it on when I need it? > > Regards > Michael Knill > > From: Michael Knill <mic...@ip...> > Reply-To: AstLinux List <ast...@li...> > Date: Wednesday, 30 August 2017 at 9:01 am > To: AstLinux List <ast...@li...> > Subject: [Astlinux-users] Getting high processor load on ALIX box > > Hmm I liked it better before I implemented Monit. Blissful ignorance ☺ > > I got am email from one of my servers with the following: > Event: Resource limit matched > Service 3016-Tilton-CM1 > Date: Tue, 29 Aug 2017 16:26:14 > Action: alert > Host: 3016-Tilton-CM1 > Description: loadavg(5min) of 2.2 matches resource limit [loadavg(5min) > 2.0] > > I found this in the logs of the server: > Aug 29 16:04:23 3016-Tilton-CM1 user.info kernel: AIF:Port 0 OS fingerprint: IN=ppp0 OUT= MAC= SRC=221.122.59.98 DST=115.187.184.60 LEN=69 TOS=0x00 PREC=0x00 TTL=44 ID=31131 PROTO=UDP SPT=6973 DPT=0 LEN=49 > Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1023275970 nsec, over threshold of 1000000000 nsec) > Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1319566069 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1274262839 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1461235038 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:04 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1057674551 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:11 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1513263031 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1548211950 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 2129665587 nsec, over threshold of 1000000000 nsec) > > ..... and lots more > > Should I turn off the Netstat server? I assume this turns off darkstat! > > Regards > Michael Knill > > Hi Michael, > > I have a few Alix 2D13 PBX running in the field (with Asterisk 11 though). They usually have between 100 and 50 MB of free RAM. > I always create my own builds for them and leave out all packages that I don't need (e.g. netsnmp, Zabbix). > > I also don't enable Monit on Geode CPUs, cause there are some memory related issues over a longer time period. > > I you want I can send you my Buildroot .config file offlist. > Since there will be no official Alix/net5501 builds in the future, you need to build yourself anyway. > > Michael > > http://www.mksolutions.info Michael http://www.mksolutions.info ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Michael K. <li...@mk...> - 2017-08-31 06:57:14
|
> Am 31.08.2017 um 05:47 schrieb Michael Knill <mic...@ip...>: > > Ok after dropping out Monit and Darkstat and rebooting (it didn't free up the memory until I did), I now have above 50M free on my systems so that's not ideal but workable. > I will not bother upgrading just yet. Maybe next year ☺ > > Regards > Michael Knill Also Asterisk 13 needs more RAM then Asterisk 11. But if don't need PJSIP or ARI you can configure Asterisk to not load these modules. > From: Michael Knill <mic...@ip...> > Reply-To: AstLinux List <ast...@li...> > Date: Wednesday, 30 August 2017 at 5:56 pm > To: AstLinux List <ast...@li...> > Subject: Re: [Astlinux-users] Getting high processor load on ALIX box > > Thanks Michael. I will make sure I turn off Monit on all my ALIX boxes. > I get that I can fine tune things to make them work but frankly for the money I think I will just change them all out to APU’s or not upgrade. > > Regards > Michael Knill > > From: Michael Keuter <li...@mk...> > Reply-To: AstLinux List <ast...@li...> > Date: Wednesday, 30 August 2017 at 5:40 pm > To: AstLinux List <ast...@li...> > Subject: Re: [Astlinux-users] Getting high processor load on ALIX box > > > > > Am 30.08.2017 um 05:17 schrieb Michael Knill <mic...@ip...>: > > Hmm looks like Monit will need to go as nearly 15M. > Chrony is also fairly heavy on memory. Is this all I have in 1.2.10? > Do I disable SNMP by just removing mnt/kd/snmp/snmpd.conf ? > I have PHP using 45M plus. Is this normal? Anything I can do in php.ini? > > Regards > Michael Knill > > -----Original Message----- > From: Michael Knill <mic...@ip...> > Reply-To: AstLinux List <ast...@li...> > Date: Wednesday, 30 August 2017 at 12:45 pm > To: AstLinux List <ast...@li...> > Subject: Re: [Astlinux-users] Getting high processor load on ALIX box > > Hmm Im a bit worried actually about upgrading to 1.2.10 with Asterisk 13 on my ALIX boxes. > Some sites showing 5M free. > > Regards > Michael Knill > > -----Original Message----- > From: Lonnie Abelbeck <li...@lo...> > Reply-To: AstLinux List <ast...@li...> > Date: Wednesday, 30 August 2017 at 12:13 pm > To: AstLinux List <ast...@li...> > Subject: Re: [Astlinux-users] Getting high processor load on ALIX box > > Michael, > > Since this is an ALIX box, (low RAM, low performance) best to not enable anything "extra" IMHO. > > Lonnie > > > On Aug 29, 2017, at 8:45 PM, Michael Knill <mic...@ip...> wrote: > > > > So do you think I should turn it off by default and only turn it on when I need it? > > Regards > Michael Knill > > From: Michael Knill <mic...@ip...> > Reply-To: AstLinux List <ast...@li...> > Date: Wednesday, 30 August 2017 at 9:01 am > To: AstLinux List <ast...@li...> > Subject: [Astlinux-users] Getting high processor load on ALIX box > > Hmm I liked it better before I implemented Monit. Blissful ignorance ☺ > > I got am email from one of my servers with the following: > Event: Resource limit matched > Service 3016-Tilton-CM1 > Date: Tue, 29 Aug 2017 16:26:14 > Action: alert > Host: 3016-Tilton-CM1 > Description: loadavg(5min) of 2.2 matches resource limit [loadavg(5min) > 2.0] > > I found this in the logs of the server: > Aug 29 16:04:23 3016-Tilton-CM1 user.info kernel: AIF:Port 0 OS fingerprint: IN=ppp0 OUT= MAC= SRC=221.122.59.98 DST=115.187.184.60 LEN=69 TOS=0x00 PREC=0x00 TTL=44 ID=31131 PROTO=UDP SPT=6973 DPT=0 LEN=49 > Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1023275970 nsec, over threshold of 1000000000 nsec) > Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1319566069 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1274262839 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1461235038 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:04 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1057674551 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:11 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1513263031 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1548211950 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 2129665587 nsec, over threshold of 1000000000 nsec) > > ..... and lots more > > Should I turn off the Netstat server? I assume this turns off darkstat! > > Regards > Michael Knill > > Hi Michael, > > I have a few Alix 2D13 PBX running in the field (with Asterisk 11 though). They usually have between 100 and 50 MB of free RAM. > I always create my own builds for them and leave out all packages that I don't need (e.g. netsnmp, Zabbix). > > I also don't enable Monit on Geode CPUs, cause there are some memory related issues over a longer time period. > > I you want I can send you my Buildroot .config file offlist. > Since there will be no official Alix/net5501 builds in the future, you need to build yourself anyway. > > Michael > > http://www.mksolutions.info Michael http://www.mksolutions.info |
From: Michael K. <mic...@ip...> - 2017-08-31 03:47:20
|
Ok after dropping out Monit and Darkstat and rebooting (it didn't free up the memory until I did), I now have above 50M free on my systems so that's not ideal but workable. I will not bother upgrading just yet. Maybe next year ☺ Regards Michael Knill From: Michael Knill <mic...@ip...> Reply-To: AstLinux List <ast...@li...> Date: Wednesday, 30 August 2017 at 5:56 pm To: AstLinux List <ast...@li...> Subject: Re: [Astlinux-users] Getting high processor load on ALIX box Thanks Michael. I will make sure I turn off Monit on all my ALIX boxes. I get that I can fine tune things to make them work but frankly for the money I think I will just change them all out to APU’s or not upgrade. Regards Michael Knill From: Michael Keuter <li...@mk...> Reply-To: AstLinux List <ast...@li...> Date: Wednesday, 30 August 2017 at 5:40 pm To: AstLinux List <ast...@li...> Subject: Re: [Astlinux-users] Getting high processor load on ALIX box Am 30.08.2017 um 05:17 schrieb Michael Knill <mic...@ip...<mailto:mic...@ip...>>: Hmm looks like Monit will need to go as nearly 15M. Chrony is also fairly heavy on memory. Is this all I have in 1.2.10? Do I disable SNMP by just removing mnt/kd/snmp/snmpd.conf ? I have PHP using 45M plus. Is this normal? Anything I can do in php.ini? Regards Michael Knill -----Original Message----- From: Michael Knill <mic...@ip...<mailto:mic...@ip...>> Reply-To: AstLinux List <ast...@li...<mailto:ast...@li...>> Date: Wednesday, 30 August 2017 at 12:45 pm To: AstLinux List <ast...@li...<mailto:ast...@li...>> Subject: Re: [Astlinux-users] Getting high processor load on ALIX box Hmm Im a bit worried actually about upgrading to 1.2.10 with Asterisk 13 on my ALIX boxes. Some sites showing 5M free. Regards Michael Knill -----Original Message----- From: Lonnie Abelbeck <li...@lo...<mailto:li...@lo...>> Reply-To: AstLinux List <ast...@li...<mailto:ast...@li...>> Date: Wednesday, 30 August 2017 at 12:13 pm To: AstLinux List <ast...@li...<mailto:ast...@li...>> Subject: Re: [Astlinux-users] Getting high processor load on ALIX box Michael, Since this is an ALIX box, (low RAM, low performance) best to not enable anything "extra" IMHO. Lonnie On Aug 29, 2017, at 8:45 PM, Michael Knill <mic...@ip...<mailto:mic...@ip...>> wrote: So do you think I should turn it off by default and only turn it on when I need it? Regards Michael Knill From: Michael Knill <mic...@ip...<mailto:mic...@ip...>> Reply-To: AstLinux List <ast...@li...<mailto:ast...@li...>> Date: Wednesday, 30 August 2017 at 9:01 am To: AstLinux List <ast...@li...<mailto:ast...@li...>> Subject: [Astlinux-users] Getting high processor load on ALIX box Hmm I liked it better before I implemented Monit. Blissful ignorance ☺ I got am email from one of my servers with the following: Event: Resource limit matched Service 3016-Tilton-CM1 Date: Tue, 29 Aug 2017 16:26:14 Action: alert Host: 3016-Tilton-CM1 Description: loadavg(5min) of 2.2 matches resource limit [loadavg(5min) > 2.0] I found this in the logs of the server: Aug 29 16:04:23 3016-Tilton-CM1 user.info kernel: AIF:Port 0 OS fingerprint: IN=ppp0 OUT= MAC= SRC=221.122.59.98 DST=115.187.184.60 LEN=69 TOS=0x00 PREC=0x00 TTL=44 ID=31131 PROTO=UDP SPT=6973 DPT=0 LEN=49 Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1023275970 nsec, over threshold of 1000000000 nsec) Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1319566069 nsec, over threshold of 1000000000 nsec) Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1274262839 nsec, over threshold of 1000000000 nsec) Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1461235038 nsec, over threshold of 1000000000 nsec) Aug 29 16:05:04 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1057674551 nsec, over threshold of 1000000000 nsec) Aug 29 16:05:11 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1513263031 nsec, over threshold of 1000000000 nsec) Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1548211950 nsec, over threshold of 1000000000 nsec) Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 2129665587 nsec, over threshold of 1000000000 nsec) ..... and lots more Should I turn off the Netstat server? I assume this turns off darkstat! Regards Michael Knill Hi Michael, I have a few Alix 2D13 PBX running in the field (with Asterisk 11 though). They usually have between 100 and 50 MB of free RAM. I always create my own builds for them and leave out all packages that I don't need (e.g. netsnmp, Zabbix). I also don't enable Monit on Geode CPUs, cause there are some memory related issues over a longer time period. I you want I can send you my Buildroot .config file offlist. Since there will be no official Alix/net5501 builds in the future, you need to build yourself anyway. Michael http://www.mksolutions.info [cid:image001.png@01D3225F.9DA6FB00] |
From: Cody A. <ald...@gm...> - 2017-08-30 14:04:22
|
Lonnie, I deleted the virtual Astlinux and redid it. It worked. I have no idea what went wrong the first time. -Cody On Tue, Aug 29, 2017 at 9:11 AM, Lonnie Abelbeck <li...@lo...> wrote: > Hi Cody, > > I just tried the latest VirtualBox on my Mac OS X system and I was able to > use the latest "Guest VM x86-64bit (Video Console):" Install ISO and our > instructions, and it all worked as expected. > > Your "error zeroing first 1 GB" would imply the VirtualBox virtual drive > was not created properly ... Hmmmm not sure how you could have gone wrong > there. > > I like to keep the install ISO and the created VirtualBox files in the > same folder. > > Give it another try. > > Lonnie > > > |
From: Michael K. <mic...@ip...> - 2017-08-30 07:56:12
|
Thanks Michael. I will make sure I turn off Monit on all my ALIX boxes. I get that I can fine tune things to make them work but frankly for the money I think I will just change them all out to APU’s or not upgrade. Regards Michael Knill From: Michael Keuter <li...@mk...> Reply-To: AstLinux List <ast...@li...> Date: Wednesday, 30 August 2017 at 5:40 pm To: AstLinux List <ast...@li...> Subject: Re: [Astlinux-users] Getting high processor load on ALIX box Am 30.08.2017 um 05:17 schrieb Michael Knill <mic...@ip...<mailto:mic...@ip...>>: Hmm looks like Monit will need to go as nearly 15M. Chrony is also fairly heavy on memory. Is this all I have in 1.2.10? Do I disable SNMP by just removing mnt/kd/snmp/snmpd.conf ? I have PHP using 45M plus. Is this normal? Anything I can do in php.ini? Regards Michael Knill -----Original Message----- From: Michael Knill <mic...@ip...<mailto:mic...@ip...>> Reply-To: AstLinux List <ast...@li...<mailto:ast...@li...>> Date: Wednesday, 30 August 2017 at 12:45 pm To: AstLinux List <ast...@li...<mailto:ast...@li...>> Subject: Re: [Astlinux-users] Getting high processor load on ALIX box Hmm Im a bit worried actually about upgrading to 1.2.10 with Asterisk 13 on my ALIX boxes. Some sites showing 5M free. Regards Michael Knill -----Original Message----- From: Lonnie Abelbeck <li...@lo...<mailto:li...@lo...>> Reply-To: AstLinux List <ast...@li...<mailto:ast...@li...>> Date: Wednesday, 30 August 2017 at 12:13 pm To: AstLinux List <ast...@li...<mailto:ast...@li...>> Subject: Re: [Astlinux-users] Getting high processor load on ALIX box Michael, Since this is an ALIX box, (low RAM, low performance) best to not enable anything "extra" IMHO. Lonnie On Aug 29, 2017, at 8:45 PM, Michael Knill <mic...@ip...<mailto:mic...@ip...>> wrote: So do you think I should turn it off by default and only turn it on when I need it? Regards Michael Knill From: Michael Knill <mic...@ip...<mailto:mic...@ip...>> Reply-To: AstLinux List <ast...@li...<mailto:ast...@li...>> Date: Wednesday, 30 August 2017 at 9:01 am To: AstLinux List <ast...@li...<mailto:ast...@li...>> Subject: [Astlinux-users] Getting high processor load on ALIX box Hmm I liked it better before I implemented Monit. Blissful ignorance ☺ I got am email from one of my servers with the following: Event: Resource limit matched Service 3016-Tilton-CM1 Date: Tue, 29 Aug 2017 16:26:14 Action: alert Host: 3016-Tilton-CM1 Description: loadavg(5min) of 2.2 matches resource limit [loadavg(5min) > 2.0] I found this in the logs of the server: Aug 29 16:04:23 3016-Tilton-CM1 user.info kernel: AIF:Port 0 OS fingerprint: IN=ppp0 OUT= MAC= SRC=221.122.59.98 DST=115.187.184.60 LEN=69 TOS=0x00 PREC=0x00 TTL=44 ID=31131 PROTO=UDP SPT=6973 DPT=0 LEN=49 Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1023275970 nsec, over threshold of 1000000000 nsec) Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1319566069 nsec, over threshold of 1000000000 nsec) Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1274262839 nsec, over threshold of 1000000000 nsec) Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1461235038 nsec, over threshold of 1000000000 nsec) Aug 29 16:05:04 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1057674551 nsec, over threshold of 1000000000 nsec) Aug 29 16:05:11 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1513263031 nsec, over threshold of 1000000000 nsec) Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1548211950 nsec, over threshold of 1000000000 nsec) Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 2129665587 nsec, over threshold of 1000000000 nsec) ..... and lots more Should I turn off the Netstat server? I assume this turns off darkstat! Regards Michael Knill Hi Michael, I have a few Alix 2D13 PBX running in the field (with Asterisk 11 though). They usually have between 100 and 50 MB of free RAM. I always create my own builds for them and leave out all packages that I don't need (e.g. netsnmp, Zabbix). I also don't enable Monit on Geode CPUs, cause there are some memory related issues over a longer time period. I you want I can send you my Buildroot .config file offlist. Since there will be no official Alix/net5501 builds in the future, you need to build yourself anyway. Michael http://www.mksolutions.info [cid:image001.png@01D321B9.36BF2800] |
From: Michael K. <li...@mk...> - 2017-08-30 07:39:42
|
> Am 30.08.2017 um 05:17 schrieb Michael Knill <mic...@ip...>: > > Hmm looks like Monit will need to go as nearly 15M. > Chrony is also fairly heavy on memory. Is this all I have in 1.2.10? > Do I disable SNMP by just removing mnt/kd/snmp/snmpd.conf ? > I have PHP using 45M plus. Is this normal? Anything I can do in php.ini? > > Regards > Michael Knill > > -----Original Message----- > From: Michael Knill <mic...@ip...> > Reply-To: AstLinux List <ast...@li...> > Date: Wednesday, 30 August 2017 at 12:45 pm > To: AstLinux List <ast...@li...> > Subject: Re: [Astlinux-users] Getting high processor load on ALIX box > > Hmm Im a bit worried actually about upgrading to 1.2.10 with Asterisk 13 on my ALIX boxes. > Some sites showing 5M free. > > Regards > Michael Knill > > -----Original Message----- > From: Lonnie Abelbeck <li...@lo...> > Reply-To: AstLinux List <ast...@li...> > Date: Wednesday, 30 August 2017 at 12:13 pm > To: AstLinux List <ast...@li...> > Subject: Re: [Astlinux-users] Getting high processor load on ALIX box > > Michael, > > Since this is an ALIX box, (low RAM, low performance) best to not enable anything "extra" IMHO. > > Lonnie > > > On Aug 29, 2017, at 8:45 PM, Michael Knill <mic...@ip...> wrote: > >> So do you think I should turn it off by default and only turn it on when I need it? >> >> Regards >> Michael Knill >> >> From: Michael Knill <mic...@ip...> >> Reply-To: AstLinux List <ast...@li...> >> Date: Wednesday, 30 August 2017 at 9:01 am >> To: AstLinux List <ast...@li...> >> Subject: [Astlinux-users] Getting high processor load on ALIX box >> >> Hmm I liked it better before I implemented Monit. Blissful ignorance ☺ >> >> I got am email from one of my servers with the following: >> Event: Resource limit matched >> Service 3016-Tilton-CM1 >> Date: Tue, 29 Aug 2017 16:26:14 >> Action: alert >> Host: 3016-Tilton-CM1 >> Description: loadavg(5min) of 2.2 matches resource limit [loadavg(5min) > 2.0] >> >> I found this in the logs of the server: >> Aug 29 16:04:23 3016-Tilton-CM1 user.info kernel: AIF:Port 0 OS fingerprint: IN=ppp0 OUT= MAC= SRC=221.122.59.98 DST=115.187.184.60 LEN=69 TOS=0x00 PREC=0x00 TTL=44 ID=31131 PROTO=UDP SPT=6973 DPT=0 LEN=49 >> Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1023275970 nsec, over threshold of 1000000000 nsec) >> Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1319566069 nsec, over threshold of 1000000000 nsec) >> Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1274262839 nsec, over threshold of 1000000000 nsec) >> Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1461235038 nsec, over threshold of 1000000000 nsec) >> Aug 29 16:05:04 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1057674551 nsec, over threshold of 1000000000 nsec) >> Aug 29 16:05:11 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1513263031 nsec, over threshold of 1000000000 nsec) >> Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1548211950 nsec, over threshold of 1000000000 nsec) >> Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 2129665587 nsec, over threshold of 1000000000 nsec) >> >> ..... and lots more >> >> Should I turn off the Netstat server? I assume this turns off darkstat! >> >> Regards >> Michael Knill Hi Michael, I have a few Alix 2D13 PBX running in the field (with Asterisk 11 though). They usually have between 100 and 50 MB of free RAM. I always create my own builds for them and leave out all packages that I don't need (e.g. netsnmp, Zabbix). I also don't enable Monit on Geode CPUs, cause there are some memory related issues over a longer time period. I you want I can send you my Buildroot .config file offlist. Since there will be no official Alix/net5501 builds in the future, you need to build yourself anyway. Michael http://www.mksolutions.info |
From: Michael K. <mic...@ip...> - 2017-08-30 03:17:58
|
Hmm looks like Monit will need to go as nearly 15M. Chrony is also fairly heavy on memory. Is this all I have in 1.2.10? Do I disable SNMP by just removing mnt/kd/snmp/snmpd.conf ? I have PHP using 45M plus. Is this normal? Anything I can do in php.ini? Regards Michael Knill -----Original Message----- From: Michael Knill <mic...@ip...> Reply-To: AstLinux List <ast...@li...> Date: Wednesday, 30 August 2017 at 12:45 pm To: AstLinux List <ast...@li...> Subject: Re: [Astlinux-users] Getting high processor load on ALIX box Hmm Im a bit worried actually about upgrading to 1.2.10 with Asterisk 13 on my ALIX boxes. Some sites showing 5M free. Regards Michael Knill -----Original Message----- From: Lonnie Abelbeck <li...@lo...> Reply-To: AstLinux List <ast...@li...> Date: Wednesday, 30 August 2017 at 12:13 pm To: AstLinux List <ast...@li...> Subject: Re: [Astlinux-users] Getting high processor load on ALIX box Michael, Since this is an ALIX box, (low RAM, low performance) best to not enable anything "extra" IMHO. Lonnie On Aug 29, 2017, at 8:45 PM, Michael Knill <mic...@ip...> wrote: > So do you think I should turn it off by default and only turn it on when I need it? > > Regards > Michael Knill > > From: Michael Knill <mic...@ip...> > Reply-To: AstLinux List <ast...@li...> > Date: Wednesday, 30 August 2017 at 9:01 am > To: AstLinux List <ast...@li...> > Subject: [Astlinux-users] Getting high processor load on ALIX box > > Hmm I liked it better before I implemented Monit. Blissful ignorance ☺ > > I got am email from one of my servers with the following: > Event: Resource limit matched > Service 3016-Tilton-CM1 > Date: Tue, 29 Aug 2017 16:26:14 > Action: alert > Host: 3016-Tilton-CM1 > Description: loadavg(5min) of 2.2 matches resource limit [loadavg(5min) > 2.0] > > I found this in the logs of the server: > Aug 29 16:04:23 3016-Tilton-CM1 user.info kernel: AIF:Port 0 OS fingerprint: IN=ppp0 OUT= MAC= SRC=221.122.59.98 DST=115.187.184.60 LEN=69 TOS=0x00 PREC=0x00 TTL=44 ID=31131 PROTO=UDP SPT=6973 DPT=0 LEN=49 > Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1023275970 nsec, over threshold of 1000000000 nsec) > Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1319566069 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1274262839 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1461235038 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:04 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1057674551 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:11 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1513263031 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1548211950 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 2129665587 nsec, over threshold of 1000000000 nsec) > > ..... and lots more > > Should I turn off the Netstat server? I assume this turns off darkstat! > > Regards > Michael Knill > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot_______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Michael K. <mic...@ip...> - 2017-08-30 02:44:54
|
Hmm Im a bit worried actually about upgrading to 1.2.10 with Asterisk 13 on my ALIX boxes. Some sites showing 5M free. Regards Michael Knill -----Original Message----- From: Lonnie Abelbeck <li...@lo...> Reply-To: AstLinux List <ast...@li...> Date: Wednesday, 30 August 2017 at 12:13 pm To: AstLinux List <ast...@li...> Subject: Re: [Astlinux-users] Getting high processor load on ALIX box Michael, Since this is an ALIX box, (low RAM, low performance) best to not enable anything "extra" IMHO. Lonnie On Aug 29, 2017, at 8:45 PM, Michael Knill <mic...@ip...> wrote: > So do you think I should turn it off by default and only turn it on when I need it? > > Regards > Michael Knill > > From: Michael Knill <mic...@ip...> > Reply-To: AstLinux List <ast...@li...> > Date: Wednesday, 30 August 2017 at 9:01 am > To: AstLinux List <ast...@li...> > Subject: [Astlinux-users] Getting high processor load on ALIX box > > Hmm I liked it better before I implemented Monit. Blissful ignorance ☺ > > I got am email from one of my servers with the following: > Event: Resource limit matched > Service 3016-Tilton-CM1 > Date: Tue, 29 Aug 2017 16:26:14 > Action: alert > Host: 3016-Tilton-CM1 > Description: loadavg(5min) of 2.2 matches resource limit [loadavg(5min) > 2.0] > > I found this in the logs of the server: > Aug 29 16:04:23 3016-Tilton-CM1 user.info kernel: AIF:Port 0 OS fingerprint: IN=ppp0 OUT= MAC= SRC=221.122.59.98 DST=115.187.184.60 LEN=69 TOS=0x00 PREC=0x00 TTL=44 ID=31131 PROTO=UDP SPT=6973 DPT=0 LEN=49 > Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1023275970 nsec, over threshold of 1000000000 nsec) > Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1319566069 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1274262839 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1461235038 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:04 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1057674551 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:11 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1513263031 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1548211950 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 2129665587 nsec, over threshold of 1000000000 nsec) > > ..... and lots more > > Should I turn off the Netstat server? I assume this turns off darkstat! > > Regards > Michael Knill > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot_______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Michael K. <mic...@ip...> - 2017-08-30 02:20:41
|
Thanks Lonnie. Yes its starting to get a bit tricky with the ALIX. Well next upgrade will have to be with a hardware change too. Regards Michael Knill -----Original Message----- From: Lonnie Abelbeck <li...@lo...> Reply-To: AstLinux List <ast...@li...> Date: Wednesday, 30 August 2017 at 12:13 pm To: AstLinux List <ast...@li...> Subject: Re: [Astlinux-users] Getting high processor load on ALIX box Michael, Since this is an ALIX box, (low RAM, low performance) best to not enable anything "extra" IMHO. Lonnie On Aug 29, 2017, at 8:45 PM, Michael Knill <mic...@ip...> wrote: > So do you think I should turn it off by default and only turn it on when I need it? > > Regards > Michael Knill > > From: Michael Knill <mic...@ip...> > Reply-To: AstLinux List <ast...@li...> > Date: Wednesday, 30 August 2017 at 9:01 am > To: AstLinux List <ast...@li...> > Subject: [Astlinux-users] Getting high processor load on ALIX box > > Hmm I liked it better before I implemented Monit. Blissful ignorance ☺ > > I got am email from one of my servers with the following: > Event: Resource limit matched > Service 3016-Tilton-CM1 > Date: Tue, 29 Aug 2017 16:26:14 > Action: alert > Host: 3016-Tilton-CM1 > Description: loadavg(5min) of 2.2 matches resource limit [loadavg(5min) > 2.0] > > I found this in the logs of the server: > Aug 29 16:04:23 3016-Tilton-CM1 user.info kernel: AIF:Port 0 OS fingerprint: IN=ppp0 OUT= MAC= SRC=221.122.59.98 DST=115.187.184.60 LEN=69 TOS=0x00 PREC=0x00 TTL=44 ID=31131 PROTO=UDP SPT=6973 DPT=0 LEN=49 > Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1023275970 nsec, over threshold of 1000000000 nsec) > Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1319566069 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1274262839 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1461235038 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:04 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1057674551 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:11 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1513263031 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1548211950 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 2129665587 nsec, over threshold of 1000000000 nsec) > > ..... and lots more > > Should I turn off the Netstat server? I assume this turns off darkstat! > > Regards > Michael Knill > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot_______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Tim T. <tt...@z-...> - 2017-08-30 02:19:56
|
Thanks Lonnie, I'll give these a try tomorrow. In the mean time, I've used Bitvise to get things going tonight. Thanks again. -----Original Message----- From: Lonnie Abelbeck [mailto:li...@lo...] Sent: Tuesday, August 29, 2017 10:11 PM To: AstLinux Users Mailing List Subject: Re: [Astlinux-users] Can't mount CDROM or USB mem stick Hi Tim, As far as FTP, Cody Alderson asked the same question a couple weeks ago [Astlinux-users] File Transfers From Windows to Astlinux (Asterisk box) https://sourceforge.net/p/astlinux/mailman/message/35994542/ The "FTP Server:" can be enabled via the Network tab. Keep in mind AstLinux is a network appliance, not a general purpose Linux distro ... our images are less then 50 MB. You can mount a USB drive ... -- ## insert USB flash drive, typically on /dev/sdb1 ## make a mount point mkdir /tmp/disk ## for a FAT formatted USB drive mount -t vfat /dev/sdb1 /tmp/disk ## or ## for a ISO formated USB drive mount -t iso9660 /dev/sdb1 /tmp/disk ## list files ls -l /tmp/disk/ ## unmount drive umount /tmp/disk rmdir /tmp/disk ## remove USB flash drive -- IMHO, Using "scp" or "sftp" is an easier way to securely transfer files. Lonnie On Aug 29, 2017, at 7:48 PM, Tim Turpin <tt...@z-...> wrote: > Thanks, Bitvise worked. > > Just out of curiosity, shouldn't I be able to perform ftp to the AstLinux server? > Also, what would be the proper way to mount a SATA CDROM drive? > > From: John Novack [mailto:jn...@co...] > Sent: Tuesday, August 29, 2017 8:23 PM > To: AstLinux Users Mailing List > Subject: Re: [Astlinux-users] Can't mount CDROM or USB mem stick > > Think out of the ( linux ) box. > One easy solution is to use Bitvise ( https://www.bitvise.com ) a free > solution to use from a windows machine Presents with a dual file transfer panel, and an SSH command window. > Requires no changes to the AstLinux system, though I always change the SSH port if there is off LAN access. > I have used it for some time to support a bunch of remote thin clients on the collectors peer to peer network. > > Be sure to check permissions on files transferred, as they may not be what you want. > > I feel sure there are other solutions as well. > > John Novack > > Tim Turpin wrote: > Sorry to be a pest, still a noob here. I need to be able to copy some .wav files from a Windows system to AstLinux. I tried FTP, but I can't find it on the AstLinux system. I was going to download it, but couldn't find YUM and wget kept failing. I then tried to read from a FAT formatted USB stick, but couldn't get it to mount. Then I tried a USB CDROM, same thing. I now have a SATA CD ROM plugged in, and it doesn't show up in fdisk -l. > Am I wrong in assuming that Linux commands should work as they do in Centos? > > > > ---------------------------------------------------------------------- > -------- Check out the vibrant tech community on one of the world's > most engaging tech sites, Slashdot.org! http://sdm.link/slashdot > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > -- > > Dog is my Co-pilot > ---------------------------------------------------------------------- > -------- Check out the vibrant tech community on one of the world's > most engaging tech sites, Slashdot.org! > http://sdm.link/slashdot______________________________________________ > _ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... ---------------------------------------------------------------------------- -- Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Lonnie A. <li...@lo...> - 2017-08-30 02:13:36
|
Michael, Since this is an ALIX box, (low RAM, low performance) best to not enable anything "extra" IMHO. Lonnie On Aug 29, 2017, at 8:45 PM, Michael Knill <mic...@ip...> wrote: > So do you think I should turn it off by default and only turn it on when I need it? > > Regards > Michael Knill > > From: Michael Knill <mic...@ip...> > Reply-To: AstLinux List <ast...@li...> > Date: Wednesday, 30 August 2017 at 9:01 am > To: AstLinux List <ast...@li...> > Subject: [Astlinux-users] Getting high processor load on ALIX box > > Hmm I liked it better before I implemented Monit. Blissful ignorance ☺ > > I got am email from one of my servers with the following: > Event: Resource limit matched > Service 3016-Tilton-CM1 > Date: Tue, 29 Aug 2017 16:26:14 > Action: alert > Host: 3016-Tilton-CM1 > Description: loadavg(5min) of 2.2 matches resource limit [loadavg(5min) > 2.0] > > I found this in the logs of the server: > Aug 29 16:04:23 3016-Tilton-CM1 user.info kernel: AIF:Port 0 OS fingerprint: IN=ppp0 OUT= MAC= SRC=221.122.59.98 DST=115.187.184.60 LEN=69 TOS=0x00 PREC=0x00 TTL=44 ID=31131 PROTO=UDP SPT=6973 DPT=0 LEN=49 > Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1023275970 nsec, over threshold of 1000000000 nsec) > Aug 29 16:04:56 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1319566069 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1274262839 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:02 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1461235038 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:04 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1057674551 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:11 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 1513263031 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: pcap_dispatch took too long (took 1548211950 nsec, over threshold of 1000000000 nsec) > Aug 29 16:05:14 3016-Tilton-CM1 daemon.debug darkstat[1424]: WARNING: event processing took longer than a second (took 2129665587 nsec, over threshold of 1000000000 nsec) > > ..... and lots more > > Should I turn off the Netstat server? I assume this turns off darkstat! > > Regards > Michael Knill > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot_______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Lonnie A. <li...@lo...> - 2017-08-30 02:11:33
|
Hi Tim, As far as FTP, Cody Alderson asked the same question a couple weeks ago [Astlinux-users] File Transfers From Windows to Astlinux (Asterisk box) https://sourceforge.net/p/astlinux/mailman/message/35994542/ The "FTP Server:" can be enabled via the Network tab. Keep in mind AstLinux is a network appliance, not a general purpose Linux distro ... our images are less then 50 MB. You can mount a USB drive ... -- ## insert USB flash drive, typically on /dev/sdb1 ## make a mount point mkdir /tmp/disk ## for a FAT formatted USB drive mount -t vfat /dev/sdb1 /tmp/disk ## or ## for a ISO formated USB drive mount -t iso9660 /dev/sdb1 /tmp/disk ## list files ls -l /tmp/disk/ ## unmount drive umount /tmp/disk rmdir /tmp/disk ## remove USB flash drive -- IMHO, Using "scp" or "sftp" is an easier way to securely transfer files. Lonnie On Aug 29, 2017, at 7:48 PM, Tim Turpin <tt...@z-...> wrote: > Thanks, Bitvise worked. > > Just out of curiosity, shouldn’t I be able to perform ftp to the AstLinux server? > Also, what would be the proper way to mount a SATA CDROM drive? > > From: John Novack [mailto:jn...@co...] > Sent: Tuesday, August 29, 2017 8:23 PM > To: AstLinux Users Mailing List > Subject: Re: [Astlinux-users] Can't mount CDROM or USB mem stick > > Think out of the ( linux ) box. > One easy solution is to use Bitvise ( https://www.bitvise.com ) a free solution to use from a windows machine > Presents with a dual file transfer panel, and an SSH command window. > Requires no changes to the AstLinux system, though I always change the SSH port if there is off LAN access. > I have used it for some time to support a bunch of remote thin clients on the collectors peer to peer network. > > Be sure to check permissions on files transferred, as they may not be what you want. > > I feel sure there are other solutions as well. > > John Novack > > Tim Turpin wrote: > Sorry to be a pest, still a noob here. I need to be able to copy some .wav files from a Windows system to AstLinux. I tried FTP, but I can’t find it on the AstLinux system. I was going to download it, but couldn’t find YUM and wget kept failing. I then tried to read from a FAT formatted USB stick, but couldn’t get it to mount. Then I tried a USB CDROM, same thing. I now have a SATA CD ROM plugged in, and it doesn’t show up in fdisk –l. > Am I wrong in assuming that Linux commands should work as they do in Centos? > > > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > -- > > Dog is my Co-pilot > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot_______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |